Are you running Windows 7 or Server 2008? There are some important updates coming down the pike, and you need to install them if you want to keep gett
[See the full post at: Patch Lady: Preparing for Microsoft’s patch-security changes]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Patch Lady: Preparing for Microsoft’s patch-security changes
Home » Forums » Newsletter and Homepage topics » Patch Lady: Preparing for Microsoft’s patch-security changes
- This topic has 14 replies, 10 voices, and was last updated 5 years, 5 months ago.
AuthorTopicViewing 3 reply threadsAuthorReplies-
MrJimPhelps
AskWoody MVPApril 8, 2019 at 6:48 am #349734For years, Microsoft has continued to use SHA-1, assuming that the chances of a valid attack are small. Currently, Windows 10 supports both SHA-1 and the more secure SHA-2, but Win7 systems have supported only SHA-1. Later this year, however, things will change — Microsoft’s entire infrastructure and patching mechanisms will require SHA-2.
When Microsoft switches to SHA-2, there will be some old software what will no longer work, because it will be dependent on SHA-1. I predict that when this happens, there will be a lot of complaints that “Windows 10 broke my software”. That would be one way to look at it. But a more accurate way to look at it, in my opinion, is that you had some old software that the vendor refused to update to SHA-2, and now you are getting bit. In other words, it isn’t Microsoft’s fault, even though they will get blamed for it.
Same thing for SMB v.1. Windows 10-1809 defaulted to a newer version of SMB; there were likely those who blamed Windows 10, but in fact Microsoft was simply plugging a security hole; and it is easy to allow SMB v.1 if you want to.
Group "L" (Linux Mint)
with Windows 10 running in a remote session on my file server -
rc primak
AskWoody_MVPApril 8, 2019 at 9:01 am #349762
Seff
AskWoody PlusApril 8, 2019 at 9:34 am #349771Thanks for the article, Susan, most informative as ever. However:-
“I recommend you not install any of these SHA-related updates on the regular Patch Tuesdays (the second week of each month). Rather, add them at the end of the month to ensure they’re installed by themselves and that there’s no interference from feature and security patches.”
Isn’t that contrary to Microsoft’s recommendation (endorsed variously here with this month’s updates) that the SHA-related updates should be installed separately before the usual monthly quality rollup?
Just in the last few days I installed the March updates on both my Windows 7 x64 home desktops by hiding everything so as to be offered KB4490628 which I installed. Then I restored the hidden updates and installed KB4474419 followed separately by KB4489878 (quality rollup). Finally, on the one relevant machine I installed the 5 Important and checked Office 2010 updates, leaving the remaining Important but unchecked Office 2010 update untouched. I followed all appropriate “restart” prompts and left time between the different installations for things to settle down. It all went smoothly.
I hope we can get a clear recommendation in future months as to whether we have to go through this or some other somewhat tortuous procedure, or can simply install the updates in the sequence in which they are offered to us.
-
PKCano
Manager -
Seff
AskWoody PlusApril 8, 2019 at 10:46 am #349828Indeed PK, but both are considered together in Susan’s article with the conclusion – in the plural – that I quoted above, and with no suggestion that the two updates mentioned should be considered and installed differently from each other.
That is why I expressed the hope that there would be greater clarification in future months. There’s clearly confusion on Microsoft’s part in the way the updates are offered otherwise we would be offered the one that has to be installed first before being offered anything else, whereas it’s only when we have installed (or known to hide) all the others that we get offered the one that they say should have been installed first – that’s why I think that we should ensure maximum clarification each month as to how to proceed with these particular updates and any others like them.
-
PKCano
Manager -
LHiggins
AskWoody PlusApril 8, 2019 at 1:55 pm #349924OK a question. On my Win 7 laptop, I checked and was offered KB4474419 – which I installed. I rechecked and was then offered KB4490628, also installed.
Then, on my Win 7 desktop, I repeated the procedure and was offered KB4474419 and KB 4493132. Since KB 4493132 is the Win 10 nag update, I hid it, installed KB4474419 and then rescanned to get KB4490628. That never appeared – and Win Update says there are no other updates. I am Group A and pretty much just wait for Woody’s go ahead and install what he says it safe each month.
So – how will I be able to get KB4490628? Should I just download it directly since it isn’t offered – or wait till the end of the next update cycle and see if it is offered then?
-
DrBonzo
AskWoody PlusApril 8, 2019 at 2:13 pm #349928I, personally, try to do as little updating through Windows Update as possible. I’m Win 7 Pro, sp1, x64, Group B. I just download the Service Stack Updates from the catalog and manually install them. That makes it an ‘exclusive install’, as required (make sure you’ve done any required reboots from any previous patch installs and make sure to reboot if required after the SSU install – although I don’t remember a reboot being required). No fuss, no muss, works great, no resultant system issues.
1 user thanked author for this post.
-
LHiggins
AskWoody PlusApril 8, 2019 at 2:30 pm #349933Thanks! Guess I’ll reboot to be sure there are no issues and go ahead and download that one. Glad it worked fine! I have no issues on the laptop, which did get both of those this morning – but for some reason, the desktop isn’t showing KB4490628. Weird!
ETA – Just noticed the DEFCON has changed to 2 – so maybe I’ll wait till next month for it – LOL!
-
-
-
shirlswoody
AskWoody PlusApril 8, 2019 at 4:20 pm #349959First time here. Don’t know quite how to use this, and I apologize if I’m in the wrong place!! But here is my question. I have win7 on a laptop, and have never been offered KB4474419. Is there a reason that it has not appeared when MS offers its updates?? I have never searched out an update, so is it okay if I go online and download it? And install it?? (I have installed 4490628.)
-
PKCano
Manager
PerthMike
AskWoody PlusApril 8, 2019 at 9:29 pm #350022Which brings up an interesting question.
If I deploy a fresh install of Windows 7 after July/September, will it still be able to get to Windows Update to (at the very least) download the patches to update itself to the new SHA2 patch? I assume the minimum would be SP1, a pile of Servicing Stack updates and then 4484071? Or will Windows update just break altogether for PCs that are freshly built?
I guess it’s a good thing I always keep WSUSOffline up to date with a set of patches.
No matter where you go, there you are.
Viewing 3 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Login screen icon
by
CWBillow
2 hours, 22 minutes ago -
AI coming to everything
by
Susan Bradley
11 minutes ago -
Mozilla : Pocket shuts down July 8, 2025, Fakespot shuts down on July 1, 2025
by
Alex5723
9 hours, 50 minutes ago -
No Screen TurnOff???
by
CWBillow
10 hours, 11 minutes ago -
Identify a dynamic range to then be used in another formula
by
BigDaddy07
10 hours, 44 minutes ago -
InfoStealer Malware Data Breach Exposed 184 Million Logins and Passwords
by
Alex5723
22 hours, 21 minutes ago -
How well does your browser block trackers?
by
n0ads
8 hours, 38 minutes ago -
You can’t handle me
by
Susan Bradley
1 hour, 6 minutes ago -
Chrome Can Now Change Your Weak Passwords for You
by
Alex5723
1 hour, 15 minutes ago -
Microsoft: Over 394,000 Windows PCs infected by Lumma malware, affects Chrome..
by
Alex5723
1 day, 9 hours ago -
Signal vs Microsoft’s Recall ; By Default, Signal Doesn’t Recall
by
Alex5723
13 hours, 13 minutes ago -
Internet Archive : This is where all of The Internet is stored
by
Alex5723
1 day, 10 hours ago -
iPhone 7 Plus and the iPhone 8 on Vantage list
by
Alex5723
1 day, 10 hours ago -
Lumma malware takedown
by
EyesOnWindows
22 hours, 28 minutes ago -
“kill switches” found in Chinese made power inverters
by
Alex5723
1 day, 19 hours ago -
Windows 11 – InControl vs pausing Windows updates
by
Kathy Stevens
1 day, 18 hours ago -
Meet Gemini in Chrome
by
Alex5723
1 day, 23 hours ago -
DuckDuckGo’s Duck.ai added GPT-4o mini
by
Alex5723
1 day, 23 hours ago -
Trump signs Take It Down Act
by
Alex5723
2 days, 7 hours ago -
Do you have a maintenance window?
by
Susan Bradley
11 hours, 47 minutes ago -
Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms
by
Nibbled To Death By Ducks
1 day, 9 hours ago -
Cox Communications and Charter Communications to merge
by
not so anon
2 days, 10 hours ago -
Help with WD usb driver on Windows 11
by
Tex265
2 hours, 33 minutes ago -
hibernate activation
by
e_belmont
2 days, 19 hours ago -
Red Hat Enterprise Linux 10 with AI assistant
by
Alex5723
2 days, 23 hours ago -
Windows 11 Insider Preview build 26200.5603 released to DEV
by
joep517
3 days, 2 hours ago -
Windows 11 Insider Preview build 26120.4151 (24H2) released to BETA
by
joep517
3 days, 2 hours ago -
Fixing Windows 24H2 failed KB5058411 install
by
Alex5723
1 day, 22 hours ago -
Out of band for Windows 10
by
Susan Bradley
3 days, 6 hours ago -
Giving UniGetUi a test run.
by
RetiredGeek
3 days, 13 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.